🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
US-RI · run data-protection-2026-08-06 v13-gdpri-1.0.0
content: ai_generated 13 sources retrieved model claude-sonnet-5 ·

United States – Rhode Island

US-RI schema gdpri-v2 trajectory: not recordedhybrid regimeoverlaps: FIM, WPM, AIC

Last updated · 10 categories · 36 claims · 13 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
36Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Core statute is in force and enforceable, but coverage gaps (no ROPA duty, no DPO rule, no in-statute breach-notification provision, no cure right) leave material compliance ambiguity relative to peer state laws.

Primary frameworkRhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws § 6-48.1 et seq.
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberCore statute is in force and enforceable, but coverage gaps (no ROPA duty, no DPO rule, no in-statute breach-notification provision, no cure right) leave material compliance ambiguity relative to peer state laws.

Sub-modules (5)

Regulator And AuthorityGreen

The Rhode Island Attorney General has sole and exclusive enforcement authority over RIDTPPA violations; there is no dedicated data-protection agency.

Claims (1):

  • The Rhode Island Attorney General has sole enforcement authority over RIDTPPA and may enforce violations pursuant to RIDTPPA or the general regulatory provisions of Title 6 commercial law.

Act And InstrumentsGreen

RIDTPPA was transmitted without gubernatorial signature on 25 June 2024 and entered into force 1 January 2026, making it Rhode Island's first comprehensive consumer privacy statute.

Claims (1):

  • The Governor of Rhode Island transmitted the RIDTPPA without signature on June 25, 2024, and it entered into effect on January 1, 2026.

Material ScopeAmber

RIDTPPA applies to entities that control or process personal data of more than 35,000 Rhode Island residents, or more than 10,000 residents while deriving at least 20% of gross revenue from the sale of personal data.

Claims (1):

  • RIDTPPA applies to entities that control or process the personal information of more than 35,000 Rhode Island residents, or more than 10,000 residents while generating 20% of gross revenue from personal data sales.

Territorial ScopeAmber

Applicability turns on processing the personal data of Rhode Island 'customers' (residents in an individual/household context) rather than on the location of the controller; no explicit extraterritorial 'offering goods/services' test comparable to GDPR Art 3(2) was identified in the sources reviewed.

Claims (1):

  • A 'customer' under RIDTPPA is defined as an individual residing in Rhode Island in an individual or household context, excluding individuals acting in a commercial or employment context.

Regulator Registration And FilingAmber

No general controller registration or filing regime was identified. The AG may request disclosure of data protection assessments, and such disclosure does not waive attorney-client privilege or work-product protection over the assessment content.

Claims (1):

  • Information contained in a data protection assessment disclosed to the Attorney General does not waive attorney-client privilege or work-product protection over that content.
Category narrative89 words

Rhode Island's data-protection regime is anchored in the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), R.I. Gen. Laws Title 6, Ch. 48.1, enacted 25 June 2024 via gubernatorial transmission without signature and now IN FORCE as of 1 January 2026. The Rhode Island Attorney General (AG) is the sole regulator, with no dedicated privacy agency (unlike California's CPPA). RIDTPPA follows the Virginia/Colorado-style consumer-privacy template but is narrower than most peer states: it omits universal opt-out signal recognition, a PII definition, a statutory right-to-cure, and enhanced children's-privacy provisions.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceThe Rhode Island Attorney General has sole enforcement authority over RIDTPPA and may enforce violations pursuant to RIDTPPA or the general regulatory provisions of Title 6 commercial law.observed
  2. ConfirmedOneTrust DataGuidanceThe Governor of Rhode Island transmitted the RIDTPPA without signature on June 25, 2024, and it entered into effect on January 1, 2026.observed
  3. ConfirmedInternational Association of Privacy ProfessionalsRIDTPPA applies to entities that control or process the personal information of more than 35,000 Rhode Island residents, or more than 10,000 residents while generating 20% of gross revenue from personal data sales.observed
  4. ConfirmedOneTrust DataGuidanceA 'customer' under RIDTPPA is defined as an individual residing in Rhode Island in an individual or household context, excluding individuals acting in a commercial or employment context.observed
  5. ProbableOneTrust DataGuidanceInformation contained in a data protection assessment disclosed to the Attorney General does not waive attorney-client privilege or work-product protection over that content.observed

#

Consent and sensitive-data protections exist but the pseudonymous-data carve-out and absence of enumerated lawful bases create materially weaker protection than GDPR-aligned regimes.

Primary frameworkRIDTPPA, R.I. Gen. Laws § 6-48.1-2, § 6-48.1-4, § 6-48.1-7
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberConsent and sensitive-data protections exist but the pseudonymous-data carve-out and absence of enumerated lawful bases create materially weaker protection than GDPR-aligned regimes.

Sub-modules (4)

Lawful BasesAmber

RIDTPPA does not enumerate lawful processing bases akin to GDPR Art 6; certain processing (contract performance, warranty fulfillment, pre-contractual steps) is carved out of the Act's restrictions rather than framed as an affirmative lawful basis.

Claims (1):

  • RIDTPPA shall not be construed to prevent a controller from providing a product or service specifically requested by a customer, performing under a contract to which a customer is a party, or taking steps at a customer's request prior to entering into a contract.

Special CategoriesGreen

Sensitive data, including the personal data of a known child, may not be processed without consent; processing of a known child's data must additionally comply with COPPA, and COPPA-compliant verifiable parental consent is deemed to satisfy RIDTPPA.

Claims (1):

  • A controller shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA; controllers compliant with COPPA's verifiable parental consent requirements are deemed compliant with RIDTPPA's parental consent obligation.

Pseudonymisation And AnonymisationAmber

Personal data is defined to exclude de-identified data and publicly available information; pseudonymous data (e.g., mobile ad IDs, IP addresses) is exempted from opt-out and access-request obligations, which consumer advocates argue undermines the Act's targeted-advertising protections.

Claims (2):

  • Personal data under RIDTPPA is defined as information linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.
  • Consumer advocates raised concerns that RIDTPPA's exemption of pseudonymous data from opt-outs and access requests allows continued use of mobile ad IDs and IP addresses for granular tracking and profile sales.
Category narrative54 words

RIDTPPA does not adopt a GDPR-style enumerated lawful-bases framework; instead it relies on a notice-plus-opt-out model for ordinary processing (targeted advertising, sale, profiling), and an opt-in consent model for sensitive/special-category data, including data of known children. Pseudonymous data is excluded from several data-subject-rights obligations, a point criticized by consumer advocates as a tracking loophole.

Sources and claims (6)
  1. ConfirmedOneTrust DataGuidanceRIDTPPA shall not be construed to prevent a controller from providing a product or service specifically requested by a customer, performing under a contract to which a customer is a party, or taking steps at a customer's request prior to entering into a contract.observed
  2. ConfirmedOneTrust DataGuidanceConsent under RIDTPPA is defined as a clear, affirmative act signifying a customer's freely given, specific, informed and unambiguous agreement to processing of personal data.observed
  3. ConfirmedOneTrust DataGuidanceA controller must provide a mechanism to grant and revoke consent and, upon receipt of a revocation, must suspend processing as soon as practicable and no later than 15 days from receipt.observed
  4. ConfirmedOneTrust DataGuidanceA controller shall not process sensitive data of a known child unless consent is obtained and the information is processed in accordance with COPPA; controllers compliant with COPPA's verifiable parental consent requirements are deemed compliant with RIDTPPA's parental consent obligation.observed
  5. ConfirmedOneTrust DataGuidancePersonal data under RIDTPPA is defined as information linked or reasonably linkable to an identified or identifiable individual and does not include de-identified data or publicly available information.observed
  6. ProbableInternational Association of Privacy ProfessionalsConsumer advocates raised concerns that RIDTPPA's exemption of pseudonymous data from opt-outs and access requests allows continued use of mobile ad IDs and IP addresses for granular tracking and profile sales.observed

#

Core rights are present and in force, but response-deadline mechanics and appeal procedures were not confirmed in the sources reviewed, creating an operational ambiguity for controllers.

Primary frameworkRIDTPPA, R.I. Gen. Laws § 6-48.1-4
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberCore rights are present and in force, but response-deadline mechanics and appeal procedures were not confirmed in the sources reviewed, creating an operational ambiguity for controllers.

Sub-modules (5)

Access RightGreen

Customers have a right to be informed and to access their personal data held by a controller.

Claims (1):

  • RIDTPPA details data subject rights including the right to be informed, access, rectification, deletion, and data portability.

Rectification And ErasureGreen

Customers have rights to rectification and deletion of their personal data.

Claims (1):

  • RIDTPPA details data subject rights including the right to be informed, access, rectification, deletion, and data portability.

Restriction And ObjectionGreen

Customers may opt out of processing for targeted advertising, and of profiling in furtherance of solely automated decisions producing legal or similarly significant effects.

Claims (1):

  • RIDTPPA provides customers the right to opt out of processing for targeted advertising, profiling, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.

Data PortabilityGreen

Customers have a right to data portability under RIDTPPA.

Claims (1):

  • RIDTPPA details data subject rights including the right to be informed, access, rectification, deletion, and data portability.

Deadlines And Response WindowsRed

No RIDTPPA-specific statutory response-window (e.g., a 45-day cycle) could be confirmed from the sources reviewed; this is a research gap requiring primary-statute verification.

Absence provenance: not recorded. Searched: not recorded.

Category narrative75 words

RIDTPPA grants Rhode Island customers rights to be informed, access, rectify, delete, port their data, and opt out of processing for targeted advertising, sale, and profiling in furtherance of solely automated decisions producing legal or similarly significant effects. The Act does not codify a specific response-window deadline or appeal mechanism comparable to peer states (e.g., Connecticut/Virginia's 45+45-day cycle); this specific procedural detail could not be confirmed from available sources and is flagged as a gap.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceRIDTPPA details data subject rights including the right to be informed, access, rectification, deletion, and data portability.observed
  2. ConfirmedOneTrust DataGuidanceRIDTPPA provides customers the right to opt out of processing for targeted advertising, profiling, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.observed

#

DPIA and processor-contract duties are in force and material, but the explicit absence of ROPA and DPO obligations, plus reliance on a separate statute for breach notification, represents a materially incomplete accountability framework relative to GDPR-aligned regimes.

Primary frameworkRIDTPPA, R.I. Gen. Laws § 6-48.1-7; RI Identity Theft Protection Act of 2015, R.I. Gen. Laws § 11-49.3 et seq.
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberDPIA and processor-contract duties are in force and material, but the explicit absence of ROPA and DPO obligations, plus reliance on a separate statute for breach notification, represents a materially incomplete accountability framework relative to GDPR-aligned regimes.

Sub-modules (7)

Accountability And DpiaGreen

Controllers must conduct and document a data protection assessment for processing that presents a heightened risk of harm, including targeted advertising, sale of personal data, certain profiling, and sensitive-data processing. This obligation is prospective only, applying to processing activities created or generated after 1 January 2026.

Claims (2):

  • A controller shall conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a customer, including processing for targeted advertising, sale of personal data, and certain profiling.
  • Data protection assessment requirements apply only to processing activities created or generated after January 1, 2026, and are not retroactive.

Dpo RequirementsRed

RIDTPPA does not specifically address data protection officer appointment requirements.

Claims (1):

  • RIDTPPA does not specifically address data protection officer appointments.

Ropa RequirementsRed

RIDTPPA does not oblige controllers or processors to create and maintain records of processing activities.

Claims (1):

  • RIDTPPA does not oblige controllers or processors to create and maintain data processing records.

Joint Controller ArrangementsGreen

Controller-processor contracts must require confidentiality, deletion/return of data at the end of services, cooperation with compliance demonstrations and assessments, and written-contract flow-down obligations to subcontractors after affording the controller an opportunity to object.

Claims (1):

  • Processor contracts must require confidentiality, deletion or return of personal data at the end of services, cooperation with controller compliance demonstrations, and written flow-down of processor obligations to subcontractors after the controller is given an opportunity to object.

Security MeasuresGreen

Controllers must establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

Claims (1):

  • RIDTPPA establishes obligations for controllers and processors to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.

Breach NotificationAmber

RIDTPPA does not itself contain breach-notification provisions; notification obligations instead arise under the separate RI Identity Theft Protection Act of 2015, which requires notice to the Attorney General and consumer reporting agencies within 45 days when a breach affects more than 500 Rhode Island residents.

Claims (2):

  • Under the Rhode Island Identity Theft Protection Act of 2015, any person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected consumers, the Attorney General, and consumer reporting agencies if more than 500 consumers may have been affected by a breach.
  • The Rhode Island Attorney General's Office must be notified within 45 days any time a data breach results in personal data of more than 500 Rhode Islanders being exposed.

Retention And DisposalRed

No RIDTPPA-specific data-retention-limit or disposal-duty provision was confirmed in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative76 words

RIDTPPA imposes a security-of-processing duty and requires data protection assessments (DPIAs) for heightened-risk processing (targeted advertising, sale of data, certain profiling, and sensitive-data processing), with recognition of assessments performed to satisfy other laws and privilege protection for AG-disclosed assessments. Notably, RIDTPPA does NOT impose a general records-of-processing (ROPA) duty and does NOT specifically address DPO appointment. Breach notification is not addressed within RIDTPPA itself but is governed by the separate Identity Theft Protection Act of 2015.

Sources and claims (8)
  1. ConfirmedOneTrust DataGuidanceA controller shall conduct and document a data protection assessment for each processing activity that presents a heightened risk of harm to a customer, including processing for targeted advertising, sale of personal data, and certain profiling.observed
  2. ConfirmedOneTrust DataGuidanceData protection assessment requirements apply only to processing activities created or generated after January 1, 2026, and are not retroactive.observed
  3. ConfirmedOneTrust DataGuidanceRIDTPPA does not specifically address data protection officer appointments.observed
  4. ConfirmedOneTrust DataGuidanceRIDTPPA does not oblige controllers or processors to create and maintain data processing records.observed
  5. ConfirmedOneTrust DataGuidanceProcessor contracts must require confidentiality, deletion or return of personal data at the end of services, cooperation with controller compliance demonstrations, and written flow-down of processor obligations to subcontractors after the controller is given an opportunity to object.observed
  6. ConfirmedOneTrust DataGuidanceRIDTPPA establishes obligations for controllers and processors to establish, implement, and maintain reasonable administrative, technical, and physical data security practices.observed
  7. ConfirmedOneTrust DataGuidanceUnder the Rhode Island Identity Theft Protection Act of 2015, any person that stores, owns, collects, processes, maintains, acquires, uses, or licenses data including personal information must notify affected consumers, the Attorney General, and consumer reporting agencies if more than 500 consumers may have been affected by a breach.observed
  8. ConfirmedState of Rhode IslandThe Rhode Island Attorney General's Office must be notified within 45 days any time a data breach results in personal data of more than 500 Rhode Islanders being exposed.observed

#

No comprehensive cross-border transfer regime exists under RIDTPPA or any identified Rhode Island sectoral statute; this is a genuine regulatory gap rather than a research omission.

Supervisory authorityRhode Island Attorney General
Traffic-light rationale — RedNo comprehensive cross-border transfer regime exists under RIDTPPA or any identified Rhode Island sectoral statute; this is a genuine regulatory gap rather than a research omission.

Sub-modules (6)

Transfer MechanismsRed

No RIDTPPA transfer-mechanism provision (adequacy, SCCs, BCRs, derogations) was identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy ReceivedRed

Not applicable; Rhode Island, as a US state, does not participate in a GDPR-style adequacy framework and no adequacy determination regarding RI was identified.

Absence provenance: not recorded. Searched: not recorded.

Adequacy GrantedRed

Not applicable; RIDTPPA does not grant adequacy status to other jurisdictions.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsRed

No SCC or BCR framework exists under RIDTPPA.

Absence provenance: not recorded. Searched: not recorded.

Transfer Impact AssessmentRed

No transfer-impact-assessment requirement was identified under RIDTPPA; the Act's data protection assessment duty is scoped to heightened-risk domestic processing, not cross-border transfer risk specifically.

Absence provenance: not recorded. Searched: not recorded.

Data LocalisationRed

No data-localisation mandate was identified under RIDTPPA or Rhode Island sectoral law.

Absence provenance: not recorded. Searched: not recorded.

Category narrative52 words

RIDTPPA, consistent with the general pattern of US state comprehensive privacy statutes, does not establish an adequacy-decision regime, cross-border transfer mechanism (SCCs/BCRs), transfer-impact-assessment requirement, or data-localisation mandate. No evidence of any such regime was found in the sources reviewed. This module is populated with an explicit gap finding rather than fabricated obligations.

#

Employment carve-out is confirmed; federal sectoral overlays are well-established but RIDTPPA-specific entity-level exemptions for HIPAA/GLBA-covered entities could not be independently confirmed from the sources reviewed.

Primary frameworkRIDTPPA § 6-48.1-2(10); federal HIPAA, GLBA, FCRA as applicable overlays
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberEmployment carve-out is confirmed; federal sectoral overlays are well-established but RIDTPPA-specific entity-level exemptions for HIPAA/GLBA-covered entities could not be independently confirmed from the sources reviewed.

Sub-modules (7)

Financial Sector OverlayAmber

The federal Gramm-Leach-Bliley Act applies to Rhode Island financial institutions regardless of RIDTPPA; each financial institution has an affirmative and continuing obligation to protect nonpublic personal information under GLBA Title V.

Claims (1):

  • Under Title V of the Gramm-Leach-Bliley Act, each financial institution has an affirmative and continuing obligation to respect customer privacy and protect the security and confidentiality of nonpublic personal information.

Health Sector OverlayAmber

HIPAA applies federally to covered entities and business associates in Rhode Island. A pending state bill (House Bill 5857) would mandate additional health-data privacy policies and consumer rights for regulated entities and small businesses, but has not been confirmed as enacted.

Claims (1):

  • Rhode Island House Bill 5857 would mandate health data privacy policies and consumer rights for regulated entities and small businesses by 2026, but its enactment status was not confirmed.

Telecoms And EprivacyRed

No Rhode Island-specific telecoms/ePrivacy overlay (comparable to EU ePrivacy Directive) was identified.

Absence provenance: not recorded. Searched: not recorded.

Employment DataGreen

RIDTPPA's definition of 'customer' excludes individuals acting in a commercial or employment context, including employees, owners, directors, officers, or contractors whose communications occur solely within their role.

Claims (1):

  • The RIDTPPA definition of 'customer' excludes individuals acting in a commercial or employment context, including employees, owners, directors, officers, or contractors of a company, partnership, sole proprietorship, nonprofit, or government agency, whose communications occur solely within that role.

Credit And ScoringAmber

The federal Fair Credit Reporting Act applies to credit-scoring activities in Rhode Island; no RIDTPPA-specific credit-scoring overlay was identified.

Absence provenance: not recorded. Searched: not recorded.

EducationAmber

The Rhode Island Attorney General joined a multistate coalition suing the U.S. Department of Education over expanded IPEDS data demands, citing student-privacy risk; a pending state bill (Senate Bill 232) would separately regulate student device data.

Claims (1):

  • The Rhode Island Attorney General joined a coalition of 17 attorneys general challenging expanded federal IPEDS survey data demands on colleges and universities, arguing the requirements jeopardize student privacy.

InsuranceRed

No Rhode Island-specific insurance-sector data privacy overlay was identified in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

RIDTPPA's 'customer' definition excludes individuals acting in a commercial or employment context, effectively carving employment data out of the consumer-privacy regime. Federal sectoral overlays (HIPAA, GLBA, FCRA) apply to covered Rhode Island entities regardless of RIDTPPA's own scope. Pending state bills (not yet enacted) would add sector-specific health-data rules (HB 5857) but these remain proposed.

Sources and claims (4)
  1. ConfirmedFederal Trade CommissionUnder Title V of the Gramm-Leach-Bliley Act, each financial institution has an affirmative and continuing obligation to respect customer privacy and protect the security and confidentiality of nonpublic personal information.observed
  2. UncertainOneTrust DataGuidanceRhode Island House Bill 5857 would mandate health data privacy policies and consumer rights for regulated entities and small businesses by 2026, but its enactment status was not confirmed.observed
  3. ConfirmedOneTrust DataGuidanceThe RIDTPPA definition of 'customer' excludes individuals acting in a commercial or employment context, including employees, owners, directors, officers, or contractors of a company, partnership, sole proprietorship, nonprofit, or government agency, whose communications occur solely within that role.observed
  4. ConfirmedState of Rhode IslandThe Rhode Island Attorney General joined a coalition of 17 attorneys general challenging expanded federal IPEDS survey data demands on colleges and universities, arguing the requirements jeopardize student privacy.observed

#

Core opt-out right for targeted advertising/sale exists and is in force, but the absence of universal opt-out signal recognition and unconfirmed dark-pattern language leave the adtech surface materially weaker than peer states.

Primary frameworkRIDTPPA § 6-48.1-4
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberCore opt-out right for targeted advertising/sale exists and is in force, but the absence of universal opt-out signal recognition and unconfirmed dark-pattern language leave the adtech surface materially weaker than peer states.

Sub-modules (6)

Cookies And TrackersAmber

No dedicated cookie/tracker-consent statute distinct from RIDTPPA's general targeted-advertising opt-out was identified.

Absence provenance: not recorded. Searched: not recorded.

Dark PatternsRed

No explicit RIDTPPA dark-pattern prohibition (comparable to Connecticut's statutory language) was confirmed in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

RIDTPPA is confirmed to omit recognition of universal opt-out mechanisms, unlike Colorado, Connecticut, Delaware, and Texas.

Claims (1):

  • Recognition of universal opt-out mechanisms is among the most notable items omitted from RIDTPPA compared to other state comprehensive privacy laws.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room rule was identified under RIDTPPA.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingGreen

Customers may opt out of processing of personal data for targeted advertising and of the sale of personal data.

Claims (1):

  • RIDTPPA provides customers the right to opt out of processing for targeted advertising, profiling, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.

Direct MarketingAmber

No RIDTPPA provision specific to direct-marketing consent/suppression distinct from the general targeted-advertising opt-out was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative45 words

RIDTPPA grants an opt-out right for targeted advertising and profiling but, notably, does NOT recognize universal opt-out mechanisms (e.g., Global Privacy Control) unlike Colorado, Connecticut, Texas and others — an explicitly identified statutory omission. No dark-pattern prohibition, clean-room/data-collaboration-room rule, or direct-marketing-specific suppression regime was confirmed.

Sources and claims (1)
  1. ConfirmedInternational Association of Privacy ProfessionalsRecognition of universal opt-out mechanisms is among the most notable items omitted from RIDTPPA compared to other state comprehensive privacy laws.observed

#

The AG's DTPA-based AI guidelines are a genuine, currently-active regulatory instrument (green signal), but RIDTPPA's own ADM transparency and biometric/genetic-specific rules remain thin or pending, holding the overall module at amber.

Primary frameworkRIDTPPA § 6-48.1-4; RI Deceptive Trade Practices Act, R.I. Gen. Laws § 6-13.1 et seq. (AI Guidelines)
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberThe AG's DTPA-based AI guidelines are a genuine, currently-active regulatory instrument (green signal), but RIDTPPA's own ADM transparency and biometric/genetic-specific rules remain thin or pending, holding the overall module at amber.

Sub-modules (6)

Profiling RestrictionsGreen

Customers may opt out of profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.

Claims (1):

  • RIDTPPA provides customers the right to opt out of processing for targeted advertising, profiling, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.

Automated Decision Making TransparencyAmber

RIDTPPA's ADM-related right is limited to an opt-out; no explicit transparency/explanation right was confirmed beyond that opt-out.

Claims (1):

  • RIDTPPA provides customers the right to opt out of processing for targeted advertising, profiling, or profiling in furtherance of solely automated decisions that produce legal or similarly significant effects concerning the customer.

Ai Risk AssessmentsAmber

The RI Attorney General has issued Guidelines to Prevent Deceptive Trade Practices in the Use of AI Decision-Making that Impacts Rights, Opportunities, or Access to Resources or Services, using existing DTPA authority (subpoena power, rulemaking, hearings) rather than dedicated AI legislation. Separate pending bills (HB 7786 risk/impact assessments; SB 627 algorithmic discrimination protections; SB 358 AI developer strict liability) have not been confirmed as enacted.

Claims (2):

  • The Rhode Island Attorney General has promulgated Guidelines to Prevent Deceptive Trade Practices in the Use of Artificial Intelligence Decision-Making that Impacts Rights, Opportunities, or Access to Resources or Services under R.I. Gen. Laws § 6-13.1 et seq.
  • The Attorney General has and will use existing Deceptive Trade Practices Act authority to enforce against unfair and deceptive practices in the marketing and use of algorithmic and AI-driven software products, while evaluating whether additional AI-specific regulation is necessary.

Biometric RegimeRed

No dedicated Rhode Island biometric-data statute (facial recognition, fingerprint, gait) was identified; RIDTPPA's general sensitive-data consent requirement would apply to the extent biometric data falls within its sensitive-data definition, but this could not be independently confirmed.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataAmber

Rhode Island Senate Bill 767 seeks to establish a Genetic Information Privacy Act with strict consumer consent and disclosure regulations, but has not been confirmed as enacted.

Claims (1):

  • Rhode Island's Senate Bill 767 seeks to safeguard genetic information privacy through strict consumer consent and data disclosure regulations.

State Surveillance CarveoutsAmber

RIDTPPA does not apply to state bodies, authorities, boards, bureaus, commissions, districts, or agencies of Rhode Island or any political subdivision thereof, effectively carving out government surveillance/processing from the Act's scope.

Claims (1):

  • RIDTPPA further provides that it does not apply to any state body, authority, board, bureau, or commission, district, or agency of Rhode Island or any political subdivision of Rhode Island.
Category narrative95 words

RIDTPPA provides an opt-out right for profiling in furtherance of solely automated decisions producing legal or similarly significant effects. Separately and significantly, the Rhode Island Attorney General has promulgated 'Guidelines to Prevent Deceptive Trade Practices in the Use of Artificial Intelligence Decision-Making that Impacts Rights, Opportunities, or Access to Resources or Services' under the Deceptive Trade Practices Act (DTPA), giving the AG direct rulemaking and enforcement authority over harmful AI decision systems independent of RIDTPPA. Several AI- and biometric-adjacent bills (algorithmic discrimination, AI developer liability, genetic information privacy) remain pending/proposed and are not yet enacted.

Sources and claims (4)
  1. ConfirmedState of Rhode IslandThe Rhode Island Attorney General has promulgated Guidelines to Prevent Deceptive Trade Practices in the Use of Artificial Intelligence Decision-Making that Impacts Rights, Opportunities, or Access to Resources or Services under R.I. Gen. Laws § 6-13.1 et seq.observed
  2. ConfirmedState of Rhode IslandThe Attorney General has and will use existing Deceptive Trade Practices Act authority to enforce against unfair and deceptive practices in the marketing and use of algorithmic and AI-driven software products, while evaluating whether additional AI-specific regulation is necessary.observed
  3. UncertainOneTrust DataGuidanceRhode Island's Senate Bill 767 seeks to safeguard genetic information privacy through strict consumer consent and data disclosure regulations.observed
  4. ConfirmedOneTrust DataGuidanceRIDTPPA further provides that it does not apply to any state body, authority, board, bureau, or commission, district, or agency of Rhode Island or any political subdivision of Rhode Island.observed

#

Baseline COPPA-aligned protection for known children exists and is in force, but the confirmed absence of enhanced/teen-specific protections and the pending (not enacted) status of supplementary bills leave the module materially incomplete.

Primary frameworkRIDTPPA § 6-48.1-2, § 6-48.1-4(c); COPPA, 15 U.S.C. § 6501 et seq.
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberBaseline COPPA-aligned protection for known children exists and is in force, but the confirmed absence of enhanced/teen-specific protections and the pending (not enacted) status of supplementary bills leave the module materially incomplete.

Sub-modules (5)

Age VerificationAmber

RIDTPPA adopts COPPA's definition of 'child' (under 13) rather than establishing an independent age-verification standard or a broader 13-16 teen category.

Claims (1):

  • RIDTPPA provides that the term 'child' has the same meaning as in the Children's Online Privacy Protection Act of 1998 (COPPA).

Minor Profiling BansRed

No RIDTPPA-specific minor-profiling ban beyond the general adult opt-out right was confirmed; enhanced children's privacy protections were explicitly identified as absent from the statute.

Claims (1):

  • Enhanced children's privacy protections are among the most notable items omitted from RIDTPPA compared to other state comprehensive privacy laws.

Education SettingsAmber

Rhode Island Senate Bill 232 seeks to regulate student device data privacy with strict access limitations, but has not been confirmed as enacted; the RI AG separately joined multistate litigation over federal student-data demands.

Claims (1):

  • The Rhode Island Attorney General joined a coalition of 17 attorneys general challenging expanded federal IPEDS survey data demands on colleges and universities, arguing the requirements jeopardize student privacy.

Dependent AdultsRed

No Rhode Island dependent-adult-specific data-protection provision (elderly, mentally incapacitated) was identified in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Category narrative61 words

RIDTPPA's children's-data protections are tied directly to COPPA's under-13 'child' definition, with no separate 13-16 teen protections (unlike Connecticut/CPRA). 'Enhanced children's privacy protections' were explicitly identified as omitted from the statute. Pending bills (Age Appropriate Design Code HB 5830, student device data SB 232, a 2027-effective children's online safety bill SB 2406) remain proposed, not enacted. No dependent-adult-specific protections were identified.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceRIDTPPA provides that the term 'child' has the same meaning as in the Children's Online Privacy Protection Act of 1998 (COPPA).observed
  2. ConfirmedInternational Association of Privacy ProfessionalsEnhanced children's privacy protections are among the most notable items omitted from RIDTPPA compared to other state comprehensive privacy laws.observed

#

Enforcement authority and the no-private-right-of-action position are clearly established (green-level confidence), but the absence of a cure period, lack of confirmed enforcement track record, and unconfirmed regulator funding/capacity data hold the module at amber.

Primary frameworkRIDTPPA § 6-48.1-8; RI Deceptive Trade Practices Act § 6-13.1-7(c)
Supervisory authorityRhode Island Attorney General
Traffic-light rationale — AmberEnforcement authority and the no-private-right-of-action position are clearly established (green-level confidence), but the absence of a cure period, lack of confirmed enforcement track record, and unconfirmed regulator funding/capacity data hold the module at amber.

Sub-modules (6)

Regulator Powers And PenaltiesAmber

The AG has sole and exclusive enforcement authority; a fine of not less than $100 and no more than $500 per disclosure was identified for certain unauthorized-disclosure violations. Under the separately-invoked DTPA, the AG may issue subpoenas, administer oaths, conduct hearings, and promulgate rules with the force of law.

Claims (3):

  • The Rhode Island Attorney General has sole enforcement authority over RIDTPPA and may enforce violations pursuant to RIDTPPA or the general regulatory provisions of Title 6 commercial law.
  • A person or entity found in violation of certain RIDTPPA disclosure provisions shall pay a fine of not less than $100 and no more than $500 for each such disclosure.
  • Under the RI Deceptive Trade Practices Act, the Attorney General may issue subpoenas, administer oaths or affirmations, conduct hearings in aid of any investigation, and prescribe forms and promulgate rules and regulations that have the force of law.

Enforcement Activity IndexAmber

No confirmed RIDTPPA enforcement action or formal AG compliance guidance had been issued as of the most recent secondary-source snapshot reviewed; the AG's AI-focused DTPA guidelines represent the most concrete regulatory activity identified to date.

Claims (1):

  • As of the RIDTPPA legal-analysis snapshot reviewed, the Rhode Island Attorney General had not yet issued RIDTPPA-specific compliance guidance.

Regulator Funding And CapacityRed

No specific data on a dedicated RIDTPPA enforcement unit, headcount, or budget within the RI AG's office was identified in the sources reviewed.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

Because RIDTPPA forecloses a private right of action, no RIDTPPA-specific class-action mechanism exists for data subjects; general Rhode Island consumer-protection class-action avenues were not confirmed as applicable to RIDTPPA violations.

Claims (1):

  • Nothing in RIDTPPA's enforcement section shall be construed to authorize any private right of action to enforce any provision of the chapter, any regulation thereunder, or any other provision of law.

Private Right Of ActionRed

RIDTPPA explicitly states that nothing in the enforcement section shall be construed to authorize a private right of action to enforce any provision of the chapter or its regulations.

Claims (1):

  • Nothing in RIDTPPA's enforcement section shall be construed to authorize any private right of action to enforce any provision of the chapter, any regulation thereunder, or any other provision of law.

Recent Developments 180DAmber

Within the last 180 days, the most significant confirmed developments are: (1) RIDTPPA's 1 January 2026 effective date bringing the state's first comprehensive privacy law online, and (2) the RI Attorney General joining a 17-state coalition (announced within the last 180 days) suing the U.S. Department of Education over expanded IPEDS student-data demands on privacy grounds.

Claims (2):

  • The Governor of Rhode Island transmitted the RIDTPPA without signature on June 25, 2024, and it entered into effect on January 1, 2026.
  • The Rhode Island Attorney General joined a coalition of 17 attorneys general challenging expanded federal IPEDS survey data demands on colleges and universities, arguing the requirements jeopardize student privacy.
Category narrative80 words

The Rhode Island Attorney General holds exclusive RIDTPPA enforcement authority; RIDTPPA explicitly forecloses any private right of action. Notably, RIDTPPA also omits a statutory right-to-cure, unlike most peer states. Separately, the AG's DTPA authority (subpoena power, hearings, rulemaking) supports the AI-decision-making guidelines. Given the Act's 1 January 2026 effective date, no RIDTPPA enforcement actions or AG guidance had been confirmed as issued as of the most recent available secondary-source snapshot; this is flagged as an evolving area requiring primary-source monitoring.

Sources and claims (4)
  1. ProbableOneTrust DataGuidanceA person or entity found in violation of certain RIDTPPA disclosure provisions shall pay a fine of not less than $100 and no more than $500 for each such disclosure.observed
  2. ConfirmedState of Rhode IslandUnder the RI Deceptive Trade Practices Act, the Attorney General may issue subpoenas, administer oaths or affirmations, conduct hearings in aid of any investigation, and prescribe forms and promulgate rules and regulations that have the force of law.observed
  3. UncertainOneTrust DataGuidanceAs of the RIDTPPA legal-analysis snapshot reviewed, the Rhode Island Attorney General had not yet issued RIDTPPA-specific compliance guidance.observed
  4. ConfirmedOneTrust DataGuidanceNothing in RIDTPPA's enforcement section shall be construed to authorize any private right of action to enforce any provision of the chapter, any regulation thereunder, or any other provision of law.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for United States – Rhode Island
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-06. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 36 claim(s), 13 source(s) in the cumulative register.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressregulator powers and penalties
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressprivate right of action
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, controller_processor_duties, sectoral_watch (employment_data sub-module), adtech (opt_out_signals), algorithmic_biometric_and_surveillance_governance (ai_risk_assessments), children_and_vulnerable_groups (age_verification/parental_consent), and enforcement_and_redress (private_right_of_action, regulator_powers) rest on T1 (riag.ri.gov statute-adjacent/regulator pages) and T2 (AG press releases) plus corroborating T3 secondary legal analysis (DataGuidance, IAPP) with direct statutory pinpoint citations (e.g., §6-48.1-2, -4, -7, -8). cross_border_and_adequacy is a confirmed T1/T3-researched genuine regulatory gap (no such regime exists for RIDTPPA), populated with explicit absent_field_provenance rather than fabricated content. Several sub-modules (deadlines_and_response_windows, retention_and_disposal, dpo_requirements detail, biometric_regime, dependent_adults, regulator_funding_and_capacity, telecoms_and_eprivacy, clean_rooms_and_dcr, insurance) rely on T3/T4 absence-confirmation searches and are flagged red/amber with absent_field_provenance rather than asserted as populated. Pending Rhode Island bills (HB 7786, SB 627, SB 358, SB 767, HB 5830, SB 232, SB 2406, HB 5857) are consistently marked is_binding=false with Uncertain/Probable confidence since enactment status could not be confirmed as of the research date.

Unresolved questions (6):

  • Does RIDTPPA specify an exact statutory response-window (e.g., 45+45 days) and appeal mechanism for data subject requests, and if so, what is the citation?
  • Does RIDTPPA contain entity-level or data-level exemptions for HIPAA-covered entities and GLBA-regulated financial institutions comparable to peer states (Virginia, Colorado, Utah)?
  • What is the current legislative status (enacted/failed/carried over) of RI SB 767 (genetic information), HB 5830 (Age Appropriate Design Code), SB 232 (student device data), SB 2406 (children's online safety, 2027), HB 7786 (AI risk assessments), SB 627 (algorithmic discrimination), and SB 358 (AI developer liability) as of August 2026?
  • Has the Rhode Island Attorney General issued any RIDTPPA-specific enforcement actions, formal guidance, or FAQs since the 1 January 2026 effective date?
  • Does RIDTPPA include a data-retention-limitation or disposal-duty provision, and if so, what is its citation?
  • What are the precise statutory retention limits, if any, and the exact scope of the $100-$500 per-disclosure fine provision within RIDTPPA's text?

Escalate to primary-source review: yes